KASAN: null-ptr-deref Write in event_handler

10 views
Skip to first unread message

syzbot

unread,
Oct 3, 2020, 5:17:15 AM10/3/20
to syzkaller...@googlegroups.com
Hello,

syzbot found the following issue on:

HEAD commit: b09c3451 Linux 4.19.149
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1499703f900000
kernel config: https://syzkaller.appspot.com/x/.config?x=d7c6dfb55644e8fd
dashboard link: https://syzkaller.appspot.com/bug?extid=66f92fe4a74ddcc863bc
compiler: gcc (GCC) 10.1.0-syz 20200507

Unfortunately, I don't have any reproducer for this issue yet.

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+66f92f...@syzkaller.appspotmail.com

vhci_hcd vhci_hcd.0: pdev(4) rhport(4) sockfd(13)
vhci_hcd vhci_hcd.0: devid(0) speed(3) speed_str(high-speed)
vhci_hcd: connection closed
==================================================================
vhci_hcd: vhci_device speed not set
BUG: KASAN: null-ptr-deref in atomic_inc include/asm-generic/atomic-instrumented.h:109 [inline]
BUG: KASAN: null-ptr-deref in kthread_stop+0x72/0x6f0 kernel/kthread.c:558
Write of size 4 at addr 000000000000001c by task kworker/u4:2/47

vhci_hcd: Failed attach request for unsupported USB speed: UNKNOWN
CPU: 1 PID: 47 Comm: kworker/u4:2 Not tainted 4.19.149-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Workqueue: usbip_event event_handler
Call Trace:
vhci_hcd vhci_hcd.0: pdev(0) rhport(0) sockfd(3)
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x22c/0x33e lib/dump_stack.c:118
vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed)
kasan_report_error.cold+0xa7/0xb9 mm/kasan/report.c:352
vhci_hcd: connection closed
kasan_report+0x8f/0x96 mm/kasan/report.c:412
vhci_hcd: connection closed
vhci_hcd vhci_hcd.0: port 0 already used
atomic_inc include/asm-generic/atomic-instrumented.h:109 [inline]
kthread_stop+0x72/0x6f0 kernel/kthread.c:558
vhci_shutdown_connection+0x13f/0x230 drivers/usb/usbip/vhci_hcd.c:1021
event_handler+0x1a5/0x450 drivers/usb/usbip/usbip_event.c:78
process_one_work+0x796/0x14e0 kernel/workqueue.c:2155
worker_thread+0x64c/0x1130 kernel/workqueue.c:2298
kthread+0x33f/0x460 kernel/kthread.c:259
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:415
==================================================================
vhci_hcd: connection closed
usb 17-4: new full-speed USB device number 3 using vhci_hcd


---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzk...@googlegroups.com.

syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.

syzbot

unread,
Oct 3, 2020, 9:35:19 AM10/3/20
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: b09c3451 Linux 4.19.149
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=13812eeb900000
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=176f55bd900000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+66f92f...@syzkaller.appspotmail.com

vhci_hcd: release socket
vhci_hcd vhci_hcd.0: pdev(2) rhport(0) sockfd(3)
vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed)
vhci_hcd: disconnect device
==================================================================
BUG: KASAN: null-ptr-deref in atomic_inc include/asm-generic/atomic-instrumented.h:109 [inline]
BUG: KASAN: null-ptr-deref in kthread_stop+0x72/0x6f0 kernel/kthread.c:558
vhci_hcd vhci_hcd.0: pdev(5) rhport(0) sockfd(3)
Write of size 4 at addr 000000000000001c by task kworker/u4:2/47
vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed)

CPU: 0 PID: 47 Comm: kworker/u4:2 Not tainted 4.19.149-syzkaller #0
vhci_hcd vhci_hcd.0: pdev(5) rhport(1) sockfd(5)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed)
Workqueue: usbip_event event_handler
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x22c/0x33e lib/dump_stack.c:118
vhci_hcd: connection closed
vhci_hcd: connection closed
kasan_report_error.cold+0xa7/0xb9 mm/kasan/report.c:352
kasan_report+0x8f/0x96 mm/kasan/report.c:412
atomic_inc include/asm-generic/atomic-instrumented.h:109 [inline]
kthread_stop+0x72/0x6f0 kernel/kthread.c:558
vhci_shutdown_connection+0x13f/0x230 drivers/usb/usbip/vhci_hcd.c:1021
vhci_hcd vhci_hcd.0: pdev(2) rhport(1) sockfd(5)
vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed)
vhci_hcd: connection closed
vhci_hcd: connection closed
event_handler+0x1a5/0x450 drivers/usb/usbip/usbip_event.c:78
process_one_work+0x796/0x14e0 kernel/workqueue.c:2155
worker_thread+0x64c/0x1130 kernel/workqueue.c:2298
kthread+0x33f/0x460 kernel/kthread.c:259
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:415
==================================================================
vhci_hcd vhci_hcd.0: pdev(0) rhport(2) sockfd(3)

syzbot

unread,
Oct 4, 2020, 4:19:15 AM10/4/20
to syzkaller...@googlegroups.com
syzbot has found a reproducer for the following issue on:

HEAD commit: b09c3451 Linux 4.19.149
git tree: linux-4.19.y
console output: https://syzkaller.appspot.com/x/log.txt?x=1362061f900000
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=101a223f900000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=17abe497900000

IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+66f92f...@syzkaller.appspotmail.com

vhci_hcd vhci_hcd.0: pdev(1) rhport(1) sockfd(6)
vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed)
vhci_hcd vhci_hcd.0: devid(0) speed(1) speed_str(low-speed)
==================================================================
vhci_hcd: connection closed
BUG: KASAN: null-ptr-deref in atomic_inc include/asm-generic/atomic-instrumented.h:109 [inline]
BUG: KASAN: null-ptr-deref in kthread_stop+0x72/0x6f0 kernel/kthread.c:558
Write of size 4 at addr 000000000000001c by task kworker/u4:0/7

CPU: 0 PID: 7 Comm: kworker/u4:0 Not tainted 4.19.149-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Workqueue: usbip_event event_handler
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x22c/0x33e lib/dump_stack.c:118
vhci_hcd vhci_hcd.0: port 0 already used
kasan_report_error.cold+0xa7/0xb9 mm/kasan/report.c:352
kasan_report+0x8f/0x96 mm/kasan/report.c:412
atomic_inc include/asm-generic/atomic-instrumented.h:109 [inline]
kthread_stop+0x72/0x6f0 kernel/kthread.c:558
vhci_shutdown_connection+0x13f/0x230 drivers/usb/usbip/vhci_hcd.c:1021
event_handler+0x1a5/0x450 drivers/usb/usbip/usbip_event.c:78
process_one_work+0x796/0x14e0 kernel/workqueue.c:2155
worker_thread+0x64c/0x1130 kernel/workqueue.c:2298
kthread+0x33f/0x460 kernel/kthread.c:259
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:415
==================================================================
vhci_hcd vhci_hcd.0: port 1 already used
Kernel panic - not syncing: panic_on_warn set ...

CPU: 0 PID: 7 Comm: kworker/u4:0 Tainted: G B 4.19.149-syzkaller #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011
Workqueue: usbip_event event_handler
Call Trace:
__dump_stack lib/dump_stack.c:77 [inline]
dump_stack+0x22c/0x33e lib/dump_stack.c:118
panic+0x2ac/0x565 kernel/panic.c:186
kasan_end_report+0x43/0x49 mm/kasan/report.c:180
kasan_report_error.cold+0x83/0xb9 mm/kasan/report.c:359
kasan_report+0x8f/0x96 mm/kasan/report.c:412
atomic_inc include/asm-generic/atomic-instrumented.h:109 [inline]
kthread_stop+0x72/0x6f0 kernel/kthread.c:558
vhci_shutdown_connection+0x13f/0x230 drivers/usb/usbip/vhci_hcd.c:1021
event_handler+0x1a5/0x450 drivers/usb/usbip/usbip_event.c:78
process_one_work+0x796/0x14e0 kernel/workqueue.c:2155
worker_thread+0x64c/0x1130 kernel/workqueue.c:2298
kthread+0x33f/0x460 kernel/kthread.c:259
ret_from_fork+0x24/0x30 arch/x86/entry/entry_64.S:415
Kernel Offset: disabled
Rebooting in 86400 seconds..

Reply all
Reply to author
Forward
0 new messages